BIOS Firmware Verification Method, Device, Server, Storage Medium, and Program Product
Through the two-level verification mechanism of hardware digital certificate carrier and system server, the problem of low security of BIOS firmware verification is solved, and higher security and accuracy are achieved, preventing BIOS firmware from being tampered with, and improving the security and update efficiency of the system.
Patent Information
- Application Number
- CN202211008602.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-22
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2042-08-22
AI Technical Summary
In the prior art, BIOS firmware verification is not very secure and is easily tampered with by humans, resulting in system insecure.
Two-level verification is performed using hardware digital certificate carrier and system server, including first-level verification of user identity and second-level verification of BIOS firmware. By combining true random number generation of hardware digital certificate carrier and verification algorithm of system server, the randomness and accuracy of the verification process are ensured.
It improves the security of BIOS firmware verification and the overall security of the system, prevents BIOS firmware from being artificially tampered with, and improves the accuracy and efficiency of updates.
Smart Images

Figure CN115514492B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technologies, and particularly to a method, apparatus, server, storage medium, and program product for verifying BIOS firmware. Background Art
[0002] With the rapid development of information technologies, there are more and more requirements for the information security of computer systems. At present, most information security technologies can only ensure the security of the system at the application layer. However, once the system itself is aggressive, it will bring immeasurable losses to users. Therefore, it is necessary to ensure the security of the system.
[0003] In the related technologies, for the scenario of updating BIOS (Basic Input Output System) firmware, before updating the BIOS firmware, it is necessary to first verify whether the BIOS firmware is secure. When verifying whether the BIOS firmware is secure, most of them simply perform digital verification on the relevant programs of the BIOS firmware through software algorithms, and determine whether the system is secure based on the verification results of the software algorithms.
[0004] However, when using the above technologies to verify the BIOS firmware, there is a problem of low verification security. Summary of the Invention
[0005] Based on this, in view of the above technical problems, it is necessary to provide a method, apparatus, server, storage medium, and program product for verifying BIOS firmware that can improve the security of verifying BIOS firmware.
[0006] In a first aspect, the present application provides a method for verifying BIOS firmware, the method including:
[0007] Obtaining a user certificate in a hardware digital certificate carrier connected to a system server, and obtaining the BIOS firmware to be updated; the system server is a server that needs to update the BIOS firmware, and the user certificate includes user information of a user who is allowed to operate on the BIOS firmware to be updated;
[0008] Determining a primary verification result for verifying the user information in the user certificate according to the user certificate in the hardware digital certificate carrier;
[0009] Determining a secondary verification result for the BIOS firmware to be updated according to the verification operations of the hardware digital certificate carrier and the system server on the BIOS firmware to be updated respectively;
[0010] Determining whether the BIOS firmware to be updated is legal according to the primary verification result and the secondary verification result.
[0011] In this embodiment, a two-level verification method is adopted, which includes verifying the user identity and verifying the BIOS firmware using a hardware digital certificate carrier. This can avoid the problem that the BIOS firmware is still updated after being arbitrarily tampered with by humans, resulting in an insecure system in the system server, ensure the security of the BIOS firmware verification, and further enhance the security of the system. In addition, by jointly verifying the BIOS firmware using the hardware digital certificate carrier and the system server, compared with the verification process of software algorithms, the verification process is not regular, that is, it has greater randomness, so the possibility of being broken is smaller, and the obtained verification result is more accurate. Therefore, it can further ensure the security of the BIOS firmware verification and improve the security of the system.
[0012] In one embodiment, determining whether the BIOS firmware to be updated is legal according to the first-level verification result and the second-level verification result includes:
[0013] If the first-level verification result is that the user information in the user certificate is verified successfully and the second-level verification result is that the BIOS firmware to be updated is verified successfully, it is determined that the BIOS firmware to be updated is legal.
[0014] In this embodiment, only when both the user information in the user certificate and the BIOS firmware to be updated are verified successfully is it determined that the BIOS firmware to be updated is legal. This can improve the accuracy of the BIOS firmware verification and further enhance the security of the system.
[0015] In one embodiment, after determining that the BIOS firmware to be updated is legal, the method further includes:
[0016] Using the BIOS firmware to be updated to update the current BIOS firmware on the system server.
[0017] In this embodiment, after the BIOS firmware to be updated is verified successfully, the current BIOS firmware on the system can also be updated using the BIOS firmware to be updated. This can effectively and accurately update the BIOS firmware on the system server and improve the efficiency and accuracy of the update.
[0018] In one embodiment, determining the second-level verification result of the BIOS firmware to be updated according to the verification operations of the hardware digital certificate carrier and the system server on the BIOS firmware to be updated respectively includes:
[0019] Receiving the first verification result of the hardware digital certificate carrier using a standard verification algorithm to perform a verification operation on the BIOS firmware to be updated;
[0020] Use the verification algorithm preset by the system server to perform verification operations on the BIOS firmware to be updated, and determine the second verification result;
[0021] Determine the secondary verification result according to the first verification result and the second verification result.
[0022] In this embodiment, the hardware digital certificate carrier uses its own standard algorithm to verify the BIOS firmware to be updated, and the system server also uses its own algorithm to verify the BIOS firmware to be updated, and combines the verification results of the two hardware devices to determine the secondary verification result. In this way, verifying the firmware through the verification results of the two hardware devices can improve the accuracy of the verification result and ensure the security of the system.
[0023] In one of the embodiments, the above-mentioned determining the secondary verification result according to the first verification result and the second verification result includes:
[0024] If the first verification result is consistent with the second verification result, it is determined that the secondary verification result is that the BIOS firmware to be updated is successfully verified.
[0025] In this embodiment, when the verification results of the two hardware devices are consistent, it is determined that the BIOS firmware to be updated is successfully verified. In this way, the secondary verification result can be obtained more simply and quickly, and the accuracy and efficiency of the obtained secondary verification result can be improved.
[0026] In one of the embodiments, the above-mentioned determining the primary verification result for verifying the user information in the user certificate according to the user certificate in the hardware digital certificate carrier includes:
[0027] Read the user certificate from the hardware digital certificate carrier and send the user certificate to the client authentication server; the above-mentioned user certificate is used to instruct the client authentication server to perform verification processing on the user information in the user certificate and send the obtained primary verification result to the system server. The verification processing includes decryption operations and user information matching operations;
[0028] Receive the primary verification result returned by the client authentication server.
[0029] In this embodiment, by sending the user certificate read from the hardware digital certificate carrier to the client authentication server for verification processing such as decryption and information matching, and receiving the primary verification result of the user information in the user certificate, since the user information in the client authentication server is generally not tampered with, this can avoid the problem of insecure user information caused by the tampering of the user information in the hardware digital certificate carrier, thereby improving the accuracy of verifying user information and further enhancing the security of the system.
[0030] Second aspect, the present application further provides a BIOS firmware verification device, which includes:
[0031] An acquisition module, configured to acquire a user certificate in a hardware digital certificate carrier connected to the system server, and acquire the BIOS firmware to be updated; the system server is a server that needs to update the BIOS firmware, and the user certificate includes user information of a user who is allowed to operate on the BIOS firmware to be updated;
[0032] A primary verification result determination module, configured to determine a primary verification result for verifying the user information in the user certificate according to the user certificate in the hardware digital certificate carrier;
[0033] A secondary verification result determination module, configured to determine a secondary verification result for the BIOS firmware to be updated according to the verification operations of the hardware digital certificate carrier and the system server on the BIOS firmware to be updated respectively;
[0034] A verification module, configured to determine whether the BIOS firmware to be updated is legal according to the primary verification result and the secondary verification result.
[0035] Third aspect, the present application further provides a system server, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0036] Acquire a user certificate in a hardware digital certificate carrier connected to the system server, and acquire the BIOS firmware to be updated; the system server is a server that needs to update the BIOS firmware, and the user certificate includes user information of a user who is allowed to operate on the BIOS firmware to be updated;
[0037] Determine a primary verification result for verifying the user information in the user certificate according to the user certificate in the hardware digital certificate carrier;
[0038] Determine a secondary verification result for the BIOS firmware to be updated according to the verification operations of the hardware digital certificate carrier and the system server on the BIOS firmware to be updated respectively;
[0039] Determine whether the BIOS firmware to be updated is legal according to the primary verification result and the secondary verification result.
[0040] Fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0041] Obtain the user certificate in the hardware digital certificate carrier connected to the system server, and obtain the BIOS firmware to be updated; the system server is the server that needs to update the BIOS firmware, and the user certificate includes the user information of the user who is allowed to operate on the BIOS firmware to be updated;
[0042] Determine a primary verification result for verifying the user information in the user certificate according to the user certificate in the hardware digital certificate carrier;
[0043] Determine a secondary verification result for the BIOS firmware to be updated according to the verification operations of the hardware digital certificate carrier and the system server on the BIOS firmware to be updated respectively;
[0044] Determine whether the BIOS firmware to be updated is legal according to the primary verification result and the secondary verification result.
[0045] In a fifth aspect, the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the following steps are implemented:
[0046] Obtain the user certificate in the hardware digital certificate carrier connected to the system server, and obtain the BIOS firmware to be updated; the system server is the server that needs to update the BIOS firmware, and the user certificate includes the user information of the user who is allowed to operate on the BIOS firmware to be updated;
[0047] Determine a primary verification result for verifying the user information in the user certificate according to the user certificate in the hardware digital certificate carrier;
[0048] Determine a secondary verification result for the BIOS firmware to be updated according to the verification operations of the hardware digital certificate carrier and the system server on the BIOS firmware to be updated respectively;
[0049] Determine whether the BIOS firmware to be updated is legal according to the primary verification result and the secondary verification result.
[0050] The above BIOS firmware verification method, device, server, storage medium, and program product perform a primary verification on the user information in the user certificate in the hardware digital certificate carrier, and perform a secondary verification on the BIOS firmware to be updated through the system server and the hardware digital certificate carrier together, and determine whether the BIOS firmware to be updated is legal according to the results of the two-level verification; wherein, the user certificate includes the user information of the user who operates on the BIOS firmware to be updated. In this method, through the two-level verification method of verifying the user identity and using the hardware digital certificate carrier to verify the BIOS firmware, it is possible to avoid the problem that the BIOS firmware is still updated after being arbitrarily tampered with by humans, resulting in the insecurity of the system in the system server, ensure the security of the BIOS firmware verification, and further enhance the security of the system; in addition, through the joint verification of the BIOS firmware by the hardware digital certificate carrier and the system server, compared with the verification process of the software algorithm, the verification process is not regular, that is, the randomness is greater, so the possibility of being broken is smaller, and the obtained verification result is more accurate. Therefore, it can further ensure the security of the BIOS firmware verification and improve the security of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 FIG. is an application environment diagram of the BIOS firmware verification method in an embodiment;
[0052] Figure 2 FIG. is a flowchart of the BIOS firmware verification method in an embodiment;
[0053] Figure 2a FIG. is a flowchart of user registration and certificate issuance in an embodiment;
[0054] Figure 3 FIG. is a flowchart of the BIOS firmware verification method in another embodiment;
[0055] Figure 4 FIG. is a flowchart of the BIOS firmware verification method in another embodiment;
[0056] Figure 5 FIG. is a timing diagram of the BIOS firmware verification method in another embodiment;
[0057] Figure 6 FIG. is a structural block diagram of the BIOS firmware verification device in an embodiment;
[0058] Figure 7 FIG. is an internal structure diagram of the system server in an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0059] To make the objectives, technical solutions and advantages of the present application more clearly understood, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only for explaining the present application and are not used to limit the present application.
[0060] The BIOS firmware verification method provided by the embodiments of the present application can be applied to an application environment as Figure 1 shown. Among them, the hardware digital certificate carrier 102 can be connected to the system server 104 and perform data interaction. At the same time, both the hardware digital certificate carrier 102 and the system server 104 can communicate with the customer authentication server 106 through the network to implement data operations such as user information registration and verification. In addition, the hardware digital certificate carrier 102 can be a USB key, which can be a device such as a USB shield or an encryption lock. The system server 104 can be a server that needs to install or update the BIOS firmware, and of course, it can also be a server that needs to install or update other systems. The customer authentication server 106 can be an operator server, which can be configured by the operator, for example, it can be located in the operator's computer room or other locations. Both the system server 104 and the customer authentication server 106 can be implemented by an independent server or a server cluster composed of multiple servers.
[0061] In one embodiment, as Figure 2 shown, a BIOS firmware verification method is provided. Taking the method applied to the Figure 1 system server 104 as an example for description, the method may include the following steps:
[0062] S202, obtain the user certificate in the hardware digital certificate carrier connected to the system server, and obtain the BIOS firmware to be updated; the system server is a server that needs to update the BIOS firmware, and the user information of the user who is allowed to operate on the BIOS firmware to be updated is included in the user certificate.
[0063] In this step, before obtaining the user certificate in the hardware digital certificate carrier, generally, user registration and issuance of the user certificate can be performed on the hardware digital certificate carrier in advance. The specific process can be referred to Figure 2aAs shown in the figure, specifically: The digital hardware certificate carrier generates a local asymmetric key pair (including a local public key and a local private key). After that, the digital hardware certificate carrier packages the user information (the user information includes the user's ID number, mobile phone number, name, fingerprint, user password, etc.), and sends the packaged user information and the local public key to the customer authentication server to request registration. The customer authentication server verifies the user information sent by the digital hardware certificate carrier. After the verification passes, it can send a certificate request to the CA (Certification Authority). The CA can issue a certificate, that is, return the issued user certificate to the customer authentication server. After that, the customer authentication server can send the user certificate to the hardware digital certificate carrier. The hardware digital certificate carrier saves the user certificate and the local private key, completing the user registration and user certificate issuance process.
[0064] After completing the user registration and user certificate issuance, when the system server needs to update the system on it with the BIOS firmware to be updated, it can obtain the user certificate in the hardware digital certificate carrier. For the way for the system server to obtain the user certificate in the hardware digital certificate carrier, it can be to insert the hardware digital certificate carrier into the external device interface of the system server, and then the security authentication module in the system server can read the user certificate in the hardware digital certificate carrier.
[0065] For the way for the system server to obtain the BIOS firmware to be updated, it can be to insert the storage device storing the BIOS firmware to be updated into the external device interface of the system server, and then the server can read the BIOS firmware to be updated from the storage device; of course, it can also be that the system server downloads the BIOS firmware to be updated from the download terminal with the BIOS to be updated; of course, it can also be other ways, which are not specifically limited here.
[0066] In addition, the system server is the server that needs to update the BIOS firmware. Here, it can be to update the non-BIOS system on the system server with the BIOS firmware to be updated, or it can be to update the BIOS system on the system server with the BIOS firmware to be updated, which is not specifically limited here.
[0067] The user certificate includes the user information of the user who is allowed to operate on the BIOS firmware to be updated. That is to say, when the user information in the user certificate corresponds to a user who has not been tampered with, generally, it is a user who has registered on the customer authentication server and is a legal user. He can operate on the BIOS firmware to be updated, which can improve the security when operating on the BIOS firmware.
[0068] S204. Determine a primary verification result for verifying the user information in the above user certificate based on the user certificate in the above hardware digital certificate carrier.
[0069] In this step, after obtaining the user certificate in the hardware digital hardware carrier, the system server can verify the user information in the user certificate to obtain a primary verification result on whether the user information in the user certificate is verified successfully; it can also be that the system server uses other devices to verify the user information in the user certificate to obtain a primary verification result on whether the user information in the user certificate is verified successfully; of course, it can also be other verification methods. In short, as long as a primary verification result can be obtained.
[0070] It should be noted that the primary verification result here includes that the user information in the user certificate is verified successfully or the user information in the user certificate is not verified successfully. This primary verification result can indicate whether the user corresponding to the user information in the user certificate is a legitimate user. By verifying the legitimacy of the user here, it is possible to prevent illegal users from operating the BIOS firmware to be updated, starting from the operator, that is, reducing the risk of updating the system of the system server from the source and improving security.
[0071] S206. Determine a secondary verification result for the BIOS firmware to be updated based on the respective verification operations of the above hardware digital certificate carrier and the system server on the BIOS firmware to be updated.
[0072] In this step, the hardware digital certificate carrier and the system server can be used to perform a legality verification operation on the BIOS firmware to be updated respectively. The specific verification operation can be a digest operation, a hash operation, etc. In short, the operation results of both on the BIOS firmware to be updated can be obtained, and then the secondary verification result can be obtained.
[0073] Among them, the secondary verification result can include that the BIOS firmware to be updated is verified successfully and the BIOS firmware to be updated is not verified successfully. This secondary verification result can indicate whether the BIOS firmware to be updated is legal. Here, the secondary verification result is the initial result of verifying the BIOS firmware to be updated, not the final verification result.
[0074] It should be noted that when the existing software algorithm is used to verify the BIOS firmware, generally, the random number generated by the random number generation function is used as the key when generating the key. The random number generated by this random number generation function has a certain regularity and belongs to a pseudo-random number. Therefore, this software algorithm is easily attacked and cracked, and the verification security of this method is not high. In this embodiment, the BIOS firmware to be updated is verified by a hardware digital certificate carrier. Compared with the verification method of the software algorithm, the encryption chip in the hardware digital certificate carrier generates a true random number through a physical noise source. The random number generated here has no regularity and is not easily attacked and cracked. Therefore, the verification security of this method is higher.
[0075] In addition, it should be noted that this step can be executed after the user information in the user certificate is successfully verified in the first-level verification in S204, or can be executed in parallel with the S204 step, and no specific limitation is made here.
[0076] S208. Determine whether the BIOS firmware to be updated is legal according to the first-level verification result and the second-level verification result.
[0077] In this step, after obtaining the first-level verification result and the second-level verification result, the legality of the BIOS firmware to be updated can be finally determined through these two-level verification results.
[0078] For example, optionally, if the first-level verification result is that the user information in the user certificate fails to be verified, that is, the user information is illegal, then regardless of whether the second-level verification result is successful or not, the system server can directly determine that the BIOS firmware to be updated is illegal and prohibit the update process using the BIOS firmware to be updated.
[0079] If the BIOS firmware to be updated determined in the second-level verification result fails to be verified, that is, it is initially determined that the BIOS firmware to be updated is illegal, then regardless of whether the first-level verification result is successful or not, the system server can directly determine that the BIOS firmware to be updated is illegal and prohibit the update process using the BIOS firmware to be updated.
[0080] If the first-level verification result is that the user information in the user certificate is successfully verified, that is, the user information is legal, and the second-level verification result is that the BIOS firmware to be updated is successfully verified, that is, it is initially determined that the BIOS firmware to be updated is legal, then it is determined that the BIOS firmware to be updated is legal.
[0081] In the above BIOS firmware verification method, primary verification is performed on the user information in the user certificate in the hardware digital certificate carrier, and secondary verification of the BIOS firmware to be updated is jointly performed by the system server and the hardware digital certificate carrier. Based on the results of the two-level verification, it is determined whether the BIOS firmware to be updated is legal. Among them, the user certificate includes the user information of the user who operates the BIOS firmware to be updated. In this method, through the two-level verification method of verifying the user identity and using the hardware digital certificate carrier to verify the BIOS firmware, it is possible to avoid the problem that the BIOS firmware is still updated after being arbitrarily tampered with by humans, resulting in the insecurity of the system in the system server, ensuring the security of the BIOS firmware verification, and thus enhancing the security of the system. In addition, through the joint verification of the BIOS firmware by the hardware digital certificate carrier and the system server, compared with the verification process of the software algorithm, the verification process is not regular, that is, more random, so the possibility of being cracked is smaller, and the obtained verification result is more accurate. Therefore, it can further ensure the security of the BIOS firmware verification and improve the security of the system.
[0082] In another embodiment, in the above embodiment, the process of verifying the BIOS firmware to be updated is mentioned. After the verification is passed / successful, in this embodiment, the BIOS firmware to be updated can also be used to update the current BIOS firmware on the system server.
[0083] Among them, the system server can read the current BIOS firmware on the system and then run the BIOS firmware to be updated to replace the current BIOS firmware, ensuring that only one version of the BIOS firmware is running on the system server.
[0084] In addition, before using the BIOS firmware to be updated to update the current BIOS firmware on the system in this embodiment, the first version number of the BIOS firmware to be updated and the second version number of the current BIOS firmware can be obtained in advance, and it is judged whether the first version number is greater than the second version number. If it is greater, the BIOS firmware to be updated can be used to replace the current BIOS firmware on the system; otherwise, there is no need to update the current BIOS firmware on the system. Through the method of judging the version number, it is possible to simply and effectively judge whether it is necessary to update the current BIOS firmware on the system, avoid the problem of losses caused by incorrect updates, and improve the accuracy of the BIOS firmware update.
[0085] In this embodiment, after the verification of the BIOS firmware to be updated is successful, the BIOS firmware to be updated can also be used to update the current BIOS firmware on the system, which can effectively and accurately update the BIOS firmware on the system server, improving the update efficiency and accuracy.
[0086] In the above embodiments, it is mentioned that both the hardware digital certificate carrier and the system server can verify the BIOS firmware to be updated. The following embodiments will detail the specific verification processes of these two.
[0087] In another embodiment, another BIOS firmware verification method is provided. Based on the above embodiments, as Figure 3 shown, the above S206 may include the following steps:
[0088] S302, receive the first verification result of the hardware digital certificate carrier using a standard verification algorithm to perform a verification operation on the BIOS firmware to be updated.
[0089] In this step, after obtaining the BIOS firmware to be updated, the system server may send the BIOS firmware to be updated to the hardware digital certificate carrier. The hardware digital certificate carrier may use the standard verification algorithm built therein to perform a verification operation on the BIOS firmware to be updated and obtain the first verification result. The standard verification algorithm here may be, for example, a digest algorithm, a hash algorithm, a signature verification algorithm, etc. For example, if the hardware digital certificate carrier uses the digest algorithm to perform a verification algorithm on the BIOS firmware to be updated, that is, perform a digest operation, then the digest corresponding to the BIOS firmware to be updated can be obtained.
[0090] After the hardware digital certificate carrier performs a verification operation on the BIOS firmware to be updated, a verification result can be obtained, denoted as the first verification result (such as the digest obtained from the above digest operation). Then, the hardware digital certificate carrier may send the obtained first verification result to the system server. Of course, it may also be that the firmware security update program module in the system server calls the interface of the standard verification algorithm in the hardware digital certificate carrier and uses this interface to perform a verification operation on the BIOS firmware to be updated to obtain the first verification result. Of course, there may also be other ways, which are not specifically limited here.
[0091] It should be noted that the standard verification algorithm here is the algorithm built in the hardware digital certificate carrier, and there is no need to develop additional software or matching hardware corresponding to this algorithm. In this way, it is relatively easy to implement and develop the process of verifying the BIOS firmware to be updated, so that the verification cost can be saved while ensuring the accuracy of verification.
[0092] S304, use the verification algorithm preset by the system server to perform a verification operation on the BIOS firmware to be updated to determine the second verification result.
[0093] In this step, after obtaining the BIOS firmware to be updated, the system server can also perform a verification operation on the BIOS firmware to be updated using a preset verification algorithm, and obtain a second verification result. The preset verification algorithm here is generally matched with the standard verification algorithm in the hardware digital hardware certificate carrier. For example, both are digest algorithms, but different types of digest algorithms can be used, which can ensure that the verification result using the hardware digital certificate carrier in the subsequent process is comparable to the verification result of the system server, that is, ensure the feasibility.
[0094] Regarding the content included in the second verification result, it can match the first verification result. For example, it is also a digest of the BIOS firmware to be updated, etc., which will not be elaborated here.
[0095] S306, determine the secondary verification result according to the first verification result and the second verification result.
[0096] In this step, after the system server obtains the first verification result of the operation of the hardware digital certificate carrier and the second verification result of its own operation, it can compare the first verification result and the second verification result to obtain a comparison result. Optionally, if the first verification result is consistent with the second verification result, it is determined that the secondary verification result is that the BIOS firmware to be updated is verified successfully; that is, if the first verification result and the second verification result are consistent, it means that the BIOS firmware to be updated has not been tampered with and its initial verification result is legal. If the first verification result and the second verification result are inconsistent, it is determined that the secondary verification result is that the BIOS firmware to be updated is verified unsuccessfully, that is, it means that the BIOS firmware to be updated may have been tampered with and may be an aggressive firmware, and subsequent update operations and other steps cannot be performed using it.
[0097] In this embodiment, the hardware digital certificate carrier uses its own standard algorithm to verify the BIOS firmware to be updated, and the system server also uses its own algorithm to verify the BIOS firmware to be updated, and combines the verification results of the two hardware to determine the secondary verification result. In this way, verifying the firmware through the verification results of the two hardware can improve the accuracy of the verification result and ensure the security of the system. In addition, when the verification results of the two hardware are consistent, it is determined that the BIOS firmware to be updated is verified successfully, which can obtain the secondary verification result more simply and quickly, and improve the accuracy and efficiency of the obtained secondary verification result.
[0098] In the above embodiment, it is mentioned that the user information in the user certificate can be verified. The following embodiment specifically describes the verification process of this user information.
[0099] In another embodiment, another BIOS firmware verification method is provided. On the basis of the above embodiment, as Figure 4As shown, the above S204 may include the following steps:
[0100] S402, read the user certificate from the hardware digital certificate carrier and send the user certificate to the client authentication server.
[0101] S404, receive the primary verification result returned by the client authentication server.
[0102] In this embodiment, after the system server reads the user certificate from the hardware digital carrier, it may send the read user certificate to the client authentication server. The user certificate is used to instruct the client authentication server to verify the user information in the user certificate and send the obtained primary verification result to the system server. The verification process includes a decryption operation and a user information matching operation.
[0103] That is to say, after the client authentication server obtains the user certificate, it can perform a decryption operation on the user certificate to obtain the user information therein, and perform a matching process on the obtained user information and the user information saved during the pre-user registration to obtain the primary verification result. The primary verification result may specifically be: when the matching is successful, it can be considered that the user information in the user certificate is successfully verified; or when the matching fails, it can be considered that the user information in the user certificate is failed to be verified. Then, the primary verification result can be sent to the system server.
[0104] In this embodiment, by sending the user certificate read from the hardware digital certificate carrier to the client authentication server for verification processes such as decryption and information matching, and receiving the primary verification result of the user information in the user certificate returned, since the user information in the client authentication server is generally not tampered with, this can avoid the problem of user information insecurity caused by the tampering of the user information in the hardware digital certificate carrier, thereby improving the accuracy of verifying user information and further enhancing the security of the system.
[0105] For the convenience of more detailed description of the technical solution of the present application, the following describes the technical solution of the present application in combination with main bodies such as the system server, the hardware digital certificate carrier, and the client authentication server. On the basis of the above embodiment, referring to Figure 5 the timing diagram shown, the above method may include the following steps:
[0106] S1, insert the hardware digital certificate carrier into the system server, read the user certificate therein, and insert the carrier of the BIOS firmware to be updated or download the BIOS firmware to be updated.
[0107] S2, the system server sends the user certificate to the client authentication server to request verification of the validity of the user certificate.
[0108] S3, the client authentication server decrypts the user certificate, matches user information, etc., to verify the validity of the user certificate and obtains the first-level verification result of the user information in the user certificate.
[0109] S4, the client authentication server sends the first-level verification result to the system server.
[0110] S5, after the first-level verification result indicates that the user certificate verification is passed, the system server receives the first verification result of the hardware digital certificate carrier verifying the BIOS firmware to be updated using a standard verification algorithm.
[0111] S6, the system server verifies and calculates the BIOS firmware to be updated using a preset verification algorithm to determine the second verification result.
[0112] S7, compare the first verification result with the second verification result. If the first verification result is consistent with the second verification result, the system server determines that the second-level verification result is that the BIOS firmware to be updated is verified successfully.
[0113] S8, determine that the BIOS firmware to be updated is legal.
[0114] S9, the system server updates the current BIOS firmware using the BIOS firmware to be updated.
[0115] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments, and the execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0116] Based on the same inventive concept, the embodiments of the present application also provide a BIOS firmware verification device for implementing the above-mentioned BIOS firmware verification method. The implementation solutions provided by this device to solve problems are similar to the implementation solutions described in the above method. Therefore, the specific limitations in one or more embodiments of the following BIOS firmware verification device can refer to the limitations on the BIOS firmware verification method in the above text, and will not be repeated here.
[0117] In one embodiment, as Figure 6As shown, a BIOS firmware verification device is provided, including: an acquisition module 11, a primary verification result determination module 12, a secondary verification result determination module 13, and a verification module 14, where:
[0118] The acquisition module 11 is configured to acquire the user certificate in the hardware digital certificate carrier connected to the system server, and acquire the BIOS firmware to be updated; the system server is the server that needs to update the BIOS firmware, and the user information of the user who is allowed to operate on the BIOS firmware to be updated is included in the user certificate;
[0119] The primary verification result determination module 12 is configured to determine the primary verification result of verifying the user information in the user certificate according to the user certificate in the hardware digital certificate carrier;
[0120] The secondary verification result determination module 13 is configured to determine the secondary verification result of the BIOS firmware to be updated according to the verification operations of the hardware digital certificate carrier and the system server on the BIOS firmware to be updated respectively;
[0121] The verification module 14 is configured to determine whether the BIOS firmware to be updated is legal according to the primary verification result and the secondary verification result.
[0122] In another embodiment, another BIOS firmware verification device is provided. On the basis of the above embodiment, the verification module 14 may include a verification unit, and the verification unit is configured to determine that the BIOS firmware to be updated is legal if the primary verification result is that the user information in the user certificate is verified successfully and the secondary verification result is that the BIOS firmware to be updated is verified successfully.
[0123] In another embodiment, another BIOS firmware verification device is provided. On the basis of the above embodiment, after the verification unit determines that the BIOS firmware to be updated is legal, the device may further include an update module, and the update module is configured to update the current BIOS firmware on the system server with the BIOS firmware to be updated.
[0124] In another embodiment, another BIOS firmware verification device is provided. On the basis of the above embodiment, the secondary verification result determination module 13 may include: a first verification unit, a second verification unit, and a determination unit, where:
[0125] The first verification unit is configured to receive the first verification result of the hardware digital certificate carrier using a standard verification algorithm to perform a verification operation on the BIOS firmware to be updated;
[0126] A second verification unit, configured to perform a verification operation on the BIOS firmware to be updated by using a verification algorithm preset by the system server, and determine a second verification result;
[0127] A determination unit, configured to determine a secondary verification result according to the first verification result and the second verification result.
[0128] Optionally, the above determination unit is specifically configured to, if the first verification result is consistent with the second verification result, determine that the secondary verification result is that the BIOS firmware to be updated is successfully verified.
[0129] In another embodiment, another BIOS firmware verification device is provided. On the basis of the above embodiment, the above first-level verification result determination module 12 may include: a sending unit and a receiving unit, where:
[0130] The sending unit is configured to read a user certificate from a hardware digital certificate carrier and send the user certificate to a client authentication server; the user certificate is used to instruct the client authentication server to perform a verification process on the user information in the user certificate and send the obtained first-level verification result to the system server, and the verification process includes a decryption operation and a user information matching operation;
[0131] The receiving unit is configured to receive the first-level verification result returned by the client authentication server.
[0132] Each module in the above BIOS firmware verification device may be implemented in whole or in part by software, hardware, and a combination thereof. The above modules may be embedded in or independent of a processor in the system server in the form of hardware, or stored in a memory in the system server in the form of software, so as to facilitate the processor to call and execute the operations corresponding to the above respective modules.
[0133] In one embodiment, a system server is provided, and its internal structure diagram may be as Figure 7 shown. The system server includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the system server is used to provide computing and control capabilities. The memory of the system server includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the system server is used to store interface data corresponding to a preset verification algorithm, etc. The network interface of the system server is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a BIOS firmware verification method is implemented.
[0134] Those skilled in the art can understand, Figure 7The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the system server to which the solution of this application is applied. The specific system server may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0135] In one embodiment, a system server is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:
[0136] Obtain the user certificate in the hardware digital certificate carrier connected to the system server, and obtain the BIOS firmware to be updated; the system server is a server that needs to update the BIOS firmware, and the user certificate includes the user information of the user who is allowed to operate on the BIOS firmware to be updated; determine the primary verification result for verifying the user information in the user certificate according to the user certificate in the above-mentioned hardware digital certificate carrier; determine the secondary verification result for the BIOS firmware to be updated according to the verification operations of the above-mentioned hardware digital certificate carrier and the system server on the BIOS firmware to be updated respectively; determine whether the BIOS firmware to be updated is legal according to the primary verification result and the secondary verification result.
[0137] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0138] If the primary verification result is that the user information in the user certificate is verified successfully, and the secondary verification result is that the BIOS firmware to be updated is verified successfully, then determine that the BIOS firmware to be updated is legal.
[0139] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0140] Use the BIOS firmware to be updated to update the current BIOS firmware on the system server.
[0141] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0142] Receive the first verification result of the verification operation of the BIOS firmware to be updated by the hardware digital certificate carrier using the standard verification algorithm; perform the verification operation on the BIOS firmware to be updated using the preset verification algorithm of the system server to determine the second verification result; determine the secondary verification result according to the first verification result and the second verification result.
[0143] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0144] If the first verification result is consistent with the second verification result, it is determined that the secondary verification result is that the BIOS firmware to be updated is verified successfully.
[0145] In one embodiment, when the processor executes a computer program, the following steps are further implemented:
[0146] Read the user certificate from the hardware digital certificate carrier and send the user certificate to the client authentication server; the user certificate is used to instruct the client authentication server to perform verification processing on the user information in the user certificate and send the obtained primary verification result to the system server, and the verification processing includes a decryption operation and a user information matching operation; receive the primary verification result returned by the client authentication server.
[0147] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0148] Obtain the user certificate in the hardware digital certificate carrier connected to the system server, and obtain the BIOS firmware to be updated; the system server is the server that needs to update the BIOS firmware, and the user certificate includes the user information of the user who is allowed to operate on the BIOS firmware to be updated; determine the primary verification result of verifying the user information in the user certificate according to the user certificate in the hardware digital certificate carrier; determine the secondary verification result of the BIOS firmware to be updated according to the verification operations of the hardware digital certificate carrier and the system server on the BIOS firmware to be updated respectively; determine whether the BIOS firmware to be updated is legal according to the primary verification result and the secondary verification result.
[0149] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0150] If the primary verification result is that the user information in the user certificate is verified successfully and the secondary verification result is that the BIOS firmware to be updated is verified successfully, it is determined that the BIOS firmware to be updated is legal.
[0151] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0152] Update the current BIOS firmware on the system server with the BIOS firmware to be updated.
[0153] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0154] The receiving hardware digital certificate carrier adopts a standard verification algorithm to perform a verification operation on the BIOS firmware to be updated, obtaining a first verification result; uses the verification algorithm preset by the system server to perform a verification operation on the BIOS firmware to be updated, determining a second verification result; and determines a secondary verification result based on the first verification result and the second verification result.
[0155] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0156] If the first verification result is consistent with the second verification result, it is determined that the secondary verification result is that the BIOS firmware to be updated is successfully verified.
[0157] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0158] Read the user certificate from the hardware digital certificate carrier and send the user certificate to the client authentication server; the above user certificate is used to instruct the client authentication server to perform a verification process on the user information in the user certificate and send the obtained primary verification result to the system server. The verification process includes a decryption operation and a user information matching operation; receive the primary verification result returned by the client authentication server.
[0159] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the following steps:
[0160] Obtain the user certificate in the hardware digital certificate carrier connected to the system server, and obtain the BIOS firmware to be updated; the system server is the server that needs to update the BIOS firmware, and the user certificate includes the user information of the user who is allowed to operate on the BIOS firmware to be updated; determine a primary verification result for verifying the user information in the above user certificate according to the user certificate in the above hardware digital certificate carrier; determine a secondary verification result for the BIOS firmware to be updated according to the verification operations of the above hardware digital certificate carrier and the system server on the BIOS firmware to be updated respectively; determine whether the BIOS firmware to be updated is legal according to the primary verification result and the secondary verification result.
[0161] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0162] If the primary verification result is that the user information in the user certificate is successfully verified and the secondary verification result is that the BIOS firmware to be updated is successfully verified, it is determined that the BIOS firmware to be updated is legal.
[0163] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0164] Update the current BIOS firmware on the system server with the BIOS firmware to be updated.
[0165] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0166] Receive the first verification result of the verification operation of the BIOS firmware to be updated by the hardware digital certificate carrier using a standard verification algorithm; perform a verification operation on the BIOS firmware to be updated using the verification algorithm preset by the system server to determine the second verification result; determine the secondary verification result according to the first verification result and the second verification result.
[0167] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0168] If the first verification result is consistent with the second verification result, determine that the secondary verification result is that the BIOS firmware to be updated is verified successfully.
[0169] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0170] Read the user certificate from the hardware digital certificate carrier and send the user certificate to the client authentication server; the above user certificate is used to instruct the client authentication server to perform a verification process on the user information in the user certificate and send the obtained primary verification result to the system server, and the verification process includes a decryption operation and a user information matching operation; receive the primary verification result returned by the client authentication server.
[0171] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0172] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0173] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0174] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A method for verifying BIOS firmware, characterized in that, The method includes: Obtaining a user certificate in a hardware digital certificate carrier connected to a system server, and obtaining a BIOS firmware to be updated; the system server is a server that needs to update the BIOS firmware, and the user certificate includes user information of a user who is allowed to operate on the BIOS firmware to be updated; Reading the user certificate from the hardware digital certificate carrier, and sending the user certificate to a client authentication server; the user certificate is used to instruct the client authentication server to perform verification processing on the user information in the user certificate, and send the obtained primary verification result to the system server, and the verification processing includes a decryption operation and a user information matching operation; Receiving the primary verification result returned by the client authentication server; Receiving a first verification result of the BIOS firmware to be updated verified by the hardware digital certificate carrier using a standard verification algorithm; Performing verification operation on the BIOS firmware to be updated using a verification algorithm preset by the system server to determine a second verification result; Determining a secondary verification result according to the first verification result and the second verification result; Determining whether the BIOS firmware to be updated is legal according to the primary verification result and the secondary verification result.
2. The method according to claim 1, characterized in that, The determining whether the BIOS firmware to be updated is legal according to the primary verification result and the secondary verification result includes: If the primary verification result is that the user information in the user certificate is verified successfully, and the secondary verification result is that the BIOS firmware to be updated is verified successfully, then it is determined that the BIOS firmware to be updated is legal.
3. The method according to claim 2, characterized in that, After determining that the BIOS firmware to be updated is legal, the method further includes: Updating the current BIOS firmware on the system server with the BIOS firmware to be updated.
4. The method according to claim 1, wherein The determining the secondary verification result according to the first verification result and the second verification result includes: If the first verification result is consistent with the second verification result, then it is determined that the secondary verification result is that the BIOS firmware to be updated is verified successfully.
5. A BIOS firmware verification device, characterized in that, The device includes: An obtaining module, configured to obtain a user certificate in a hardware digital certificate carrier connected to a system server, and obtain a BIOS firmware to be updated; the system server is a server that needs to update the BIOS firmware, and the user certificate includes user information of a user who is allowed to operate on the BIOS firmware to be updated; A primary verification result determining module, configured to read the user certificate from the hardware digital certificate carrier, and send the user certificate to a client authentication server; the user certificate is used to instruct the client authentication server to perform verification processing on the user information in the user certificate, and send the obtained primary verification result to the system server, and the verification processing includes a decryption operation and a user information matching operation; receiving the primary verification result returned by the client authentication server; The secondary verification result determination module is configured to receive the first verification result of the verification operation of the BIOS firmware to be updated by the hardware digital certificate carrier using a standard verification algorithm; perform a verification operation on the BIOS firmware to be updated using a verification algorithm preset by the system server to determine a second verification result; and determine a secondary verification result according to the first verification result and the second verification result. The verification module is configured to determine whether the BIOS firmware to be updated is legal according to the primary verification result and the secondary verification result.
6. A system server, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 4 are implemented.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 4 are implemented.
8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
External device and verification updating method thereof
CN113051544A
Firmware upgrading method and device
CN114461255A